MEDIUM
GHSA-5cxf-xx9j-54jc
Multiple Cross-Site Scripting vulnerabilities in TYPO3 backend
Quick fix
GHSA-5cxf-xx9j-54jc — typo3/cms: upgrade to the fixed version with the command below.
composer require typo3/cms:^6.2.16Details
Failing to properly encode user input, several backend components are susceptible to Cross-Site Scripting, allowing authenticated editors to inject arbitrary HTML or JavaScript.
Are you affected?
Enter the version of the package you're using.